CVE-2026-19598 is a critical incorrect-authorization vulnerability in the Pods – Custom Content Types and Fields plugin for WordPress. It affects releases through 3.3.9. The Pods administrative AJAX router routes method allowlist, nonce, authentication, and capability-check failures through an error handler. In a JSON meta-box-loader compatibility path, that handler logs a failure and returns rather than terminating processing. Since the caller does not stop execution after the error handler returns, requests continue to dynamic dispatch of attacker-controlled Pods API methods despite failed access-control checks. An unauthenticated attacker can invoke privileged functionality, including user-account modification operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This two-file repository contains one Python 3 exploit program (`CVE-2026-19598.py`) and a README. It is a standalone, requests-based bulk exploitation utility rather than a Metasploit, Nuclei, or other framework module. The script normalizes target URLs, loads multiple targets from a file, probes public Pods plugin paths, extracts a version from `readme.txt` or `init.php`, and considers unknown versions potentially vulnerable. It uses a thread pool for mass scanning/exploitation, randomizes user-agent strings, disables TLS-certificate warnings/verification, prints progress/status output, and persists successful credentials. The documented attack abuses the Pods `pods_admin` AJAX action with `save_user` and `meta-box-loader=1` to create an administrator or overwrite a user password, followed by login verification. The code and README describe an active account-compromise exploit, not merely a vulnerability detector.
This repository is a small standalone Python proof-of-concept for CVE-2026-19598 targeting the WordPress Pods plugin (<= 3.3.9). It contains two files: a README describing the issue and one executable script, CVE-2026-19598.py, which is the main exploit entry point. The exploit is not a scanner or detection-only tool; it performs active exploitation. Its core capability is unauthenticated privilege escalation against a vulnerable WordPress site by sending a crafted request to /wp-admin/admin-ajax.php. The request uses the Pods AJAX action pods_admin with method save_user to modify user ID 1, setting a randomly generated email address and password and assigning the administrator role. This effectively attempts to take over or repurpose the primary WordPress account. After exploitation, the script performs post-exploitation verification by requesting /wp-login.php, optionally extracting a _wpnonce from the login page, submitting the generated credentials, and then checking /wp-admin/ for dashboard content to confirm successful administrator access. The script normalizes target URLs, uses aiohttp for asynchronous HTTP requests, disables SSL verification, and presents status output with the rich library. Repository structure is minimal and purpose-built: README.md documents the vulnerability and intended research-only use, while CVE-2026-19598.py contains helper routines for password/email generation, nonce extraction, login verification, and the single-site exploitation workflow. The exploit appears operational rather than merely demonstrative because it includes a complete exploitation path and credential verification logic, but it is still a simple standalone PoC rather than a framework-integrated or highly customizable weaponized tool.
This repository contains a single Python script, masscan.py, which functions as a multithreaded mass-exploitation tool rather than a benign detector. It reads a list of target base URLs from a user-supplied file, appends /wp-admin/admin-ajax.php to each target, and sends a crafted POST request intended to abuse a WordPress/Pods administrative AJAX action. The request uses action=pods_admin and method=save_user and supplies hardcoded account details to create a new administrator user: username admin_test, password P@ssw0rd123!, and email admin_test@test.com. The script treats HTTP 200 responses containing user_id or success as evidence of successful exploitation. Structurally, the code has two main functions: exploit_single(), which performs the HTTP POST and evaluates the response, and main(), which handles user input, file loading, concurrent execution with ThreadPoolExecutor(max_workers=10), console reporting, and writing successful targets to vulnerable.txt. There is no framework usage, no modularization, and no payload customization beyond editing the script. The exploit capability is unauthorized admin account creation on vulnerable WordPress targets, making this an operational web exploit with mass-scanning support.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical privilege escalation vulnerability caused by authorization bypass in the WordPress plugin Pods – Custom Content Types and Fields, allowing unauthenticated attackers to gain administrator privileges, reset arbitrary user passwords, and fully take over affected sites.
A critical unauthenticated file upload and remote code execution vulnerability in the Everest Forms WordPress plugin that can lead to full site takeover.
An unauthenticated privilege escalation vulnerability affecting Pods versions 3.3.9 and earlier, reportedly via the pods_admin AJAX Router.
A critical unauthenticated privilege escalation vulnerability in the Pods – Custom Content Types and Fields WordPress plugin caused by authorization bypass in the pods_admin AJAX router, allowing attackers to gain administrator privileges, reset arbitrary user passwords, and potentially fully compromise a site.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.